Managed OpenCloud 7.2 is now available on Open Edge Cloud, and every instance runs on a STIG-hardened foundation with FIPS mode enforced and FIPS 140-3 validated cryptography by default. For organizations that need real file collaboration but answer to auditors, contracting officers, or a security team that reads the fine print, this is the version worth paying attention to.
This is not a hosting account with OpenCloud installed on it. It is a dedicated, isolated OpenCloud 7.2 deployment, provisioned and operated by us on infrastructure built to a federal hardening baseline, with the security and compliance posture of the rest of the Open Edge platform underneath it.

The problem this solves
Most teams that want self-hosted file collaboration get stuck in the same place. The open-source platform is excellent and free, but standing it up so it actually meets a hardening standard is a different project entirely. You have to harden the operating system, enable and prove FIPS mode end to end, lock down identity, wire up encrypted object storage, keep it patched, and then do it all again at the next major version. The software is the easy part. The compliant, maintained, audit-ready operation of it is the work.
Managed OpenCloud 7.2 removes that work. The hardened foundation is the default, not an upgrade you have to ask for and configure.
What every instance ships with

A STIG-hardened, FIPS-enabled base. Each OpenCloud instance runs on our purpose-built hardened image: a STIG-aligned Ubuntu 24.04 build booting a dedicated FIPS kernel, with FIPS mode enforced at the operating-system and cryptographic-module level. FIPS is not one checkbox here; it holds at three layers. The kernel runs in FIPS mode. TLS terminates against a FIPS 140-3 validated module (OpenSSL 3, CMVP certificate #5115). And the OpenCloud application itself runs as our own hardened build, engineered so the cryptography inside the application operates in FIPS 140-3 mode as well, not just the transport around it.
FIPS posture verified on every deployment, automatically. “It is in FIPS mode” is something our provisioning pipeline proves, not something we assume. Every deployment ends with automated verification of the FIPS posture at both the operating-system layer and the application layer. If any check fails, the instance is not handed over. That assertion runs on every deploy and every reconfigure, so the posture cannot silently drift.
Dedicated, isolated instances. This is not shared multi-tenancy. Each customer gets their own OpenCloud instance, their own project boundary, their own storage, and their own subdomain. Your collaboration surface is not co-resident with anyone else’s.
Your domain. Instances are reachable at your own hostname with certificates managed for you and renewed automatically. There is nothing to configure and no certificate expiry to babysit.
Identity your way. Every instance provisions with one of two identity modes. Local mode runs OpenCloud’s built-in identity provider inside the instance itself: accounts and login live entirely within your deployment, with no external identity dependency at all. SSO mode federates to a full identity platform with MFA, including hardware keys, and can connect onward to your own identity provider. The same instance can start simple and move to full SSO later without a rebuild.
Object storage that does not surprise you. Files are backed by S3-compatible object storage on our own infrastructure. Each instance gets its own dedicated bucket and its own storage credentials, created automatically at provisioning time, so your file estate is not just logically separated but held under credentials that belong only to your deployment. And there are no egress fees: pulling a large dataset back out does not generate a separate bill.
A managed lifecycle. Provisioning, patching, version upgrades, backups, and monitoring are ours to run. Provisioning itself is fully automated end to end: the hardened VM, the storage, the DNS record, the certificates, the application configuration, and the final FIPS verification all come out of one pipeline, so a new instance is a same-day event rather than a project. When the next OpenCloud release lands, the migration window, the rollback plan, and the verification are our job, not a maintenance ticket aging on your team’s backlog.
Monitoring that respects the isolation. Each instance ships logs and metrics to our observability platform under its own customer tenant, isolated from every other customer’s telemetry. We watch the health of your instance without mixing your operational data with anyone else’s.
Support that routes to a real queue. Questions and issues go to a single support address, open a tracked ticket with an SLA, and get answered by the team that operates the platform.
The platform underneath

Managed OpenCloud is one application running on Open Edge Cloud, and the platform underneath is the actual product. The file-collaboration layer inherits all of it.
Security. Federated identity with MFA. Encryption at rest with customer-managed keys for volumes and object storage. File integrity monitoring and continuous configuration assessment running on the infrastructure, not bolted on afterward. Every cryptographic operation on the platform runs against a FIPS 140-3 validated module.
Compliance. Open Edge follows SOC 2 and ISO 27001 control frameworks, and the platform is engineered to the FedRAMP Moderate baseline with a control-mapping program that customers with a real compliance footprint can walk through under NDA. The platform supports HIPAA-eligible workloads. Every API and administrative action is captured in an audit trail retained in immutable, encrypted storage on a multi-year horizon and exportable on request. The file layer is part of that same audited posture, not a separate black box.
Sovereignty. The whole platform runs in US-sovereign datacenters operated by US persons, so the data-residency and jurisdictional questions have clean answers by default.
Performance. Instances run on persistent NVMe-backed storage, not spinning-disk bulk tiers, and the object-storage backend is built and tuned to carry real file estates.
Running in production today
This is not a roadmap announcement. Managed OpenCloud 7.2 instances on the hardened FIPS foundation are provisioned and in daily use right now, including an active customer proof of concept running real files on a dedicated instance. That deployment exercised the full path described above: the FIPS kernel image, the automated FIPS verification, built-in identity with no external dependency, and dedicated S3 storage on our own clusters, all provisioned by the same pipeline every future customer gets.
The platform also supports running more than one instance under a single organization. Each instance keeps its own VM, storage, domain, and identity boundary, which makes the model a fit for MSPs and resellers who want to stand up an isolated, hardened OpenCloud per client without operating any of it themselves.
Who this is for

This offering exists for organizations that cannot treat “we will harden it later” as an answer:
- Government contractors and their suppliers working under DFARS, CMMC, and similar obligations, where FIPS-validated cryptography and a documented hardening baseline are table stakes.
- Healthcare and life-sciences teams that need HIPAA-eligible file collaboration without standing up the security program themselves.
- Law and accounting firms holding client data that has to stay in a known jurisdiction with a clean chain of custody.
- Any team currently paying for a SaaS file platform and quietly worried about where the data lives and who can reach it.
- MSPs and resellers who want to offer hardened, sovereign file collaboration to their clients, one isolated instance per client, without building the platform behind it.
If your file collaboration has to satisfy a control framework and you would rather not become a full-time platform operator to get there, this is built for you.
Getting started
A Managed OpenCloud 7.2 instance can be provisioned for your organization with your domain, your choice of identity model, and storage sized to your estate. We handle the hardening, the FIPS verification, the certificates, and the ongoing operation. You get a working, audit-ready file-collaboration platform and a support queue, not a backlog of security tasks.
To see it, or to talk through moving an existing OpenCloud or legacy file platform onto a managed, hardened instance, reach out.
